RE: Help on 3550

From: Ouellette, Tim (tim.ouellette@eds.com)
Date: Sun Oct 13 2002 - 06:21:41 GMT-3


ohh, found some interesting info while searching groupstudy. Supposedly
extended acl's don't work with access-class and vty's

Check out the following

http://www.groupstudy.com/archives/ccielab/200103/msg01881.html

watch the wrap.

Tim

-----Original Message-----
From: SRINIVAS TENNETI [mailto:st_552587@yahoo.com]
Sent: Sunday, October 13, 2002 12:44 AM
To: ccielab@groupstudy.com
Subject: Help on 3550

This is the problem I have.
.2 148.4.20.0 .1

S7--------------------------------------R2
Cat3550

They are connected by FE. When I use standard
access-list on Cat3550. It works fine.

S7#sh access-lists
Standard IP access list 1
    permit 148.4.20.1 (2 matches)
Extended IP access list dhcp_glean_acl (per-user)
    permit udp any eq bootpc host 255.255.255.255 eq
bootps

R2#telnet 148.4.20.2
Trying 148.4.20.2 ... Open

S7>

If I use extended ACL then there is the problem

S7#sh ip access-lists
Extended IP access list 100
    permit tcp host 148.4.20.1 host 148.4.20.2 eq
telnet
Extended IP access list dhcp_glean_acl (per-user)
    permit udp any eq bootpc host 255.255.255.255 eq
bootps

R2#telnet 148.4.20.2
Trying 148.4.20.2 ...
% Connection refused by remote host

Thanks,

Srinivas



This archive was generated by hypermail 2.1.4 : Tue Nov 05 2002 - 08:35:45 GMT-3